First published: Mon Jul 23 2018(Updated: )
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in `aubio_pitch_set_unit` in `pitch/pitch.c`, as demonstrated by aubionotes.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/aubio | <0.4.7 | 0.4.7 |
Aubio Aubio | =0.4.6 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =42.3 | |
SUSE Linux Enterprise | =15.0 | |
debian/aubio | 0.4.9-4 0.4.9-4.3 0.4.9-4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-14522 is high (8.8).
To fix CVE-2018-14522, update to version 0.4.7 or higher.
Versions 0.4.6, 0.4.6-2, 0.4.9-4, and 0.4.9-4.3 of aubio are affected by CVE-2018-14522.
The CWE ID for CVE-2018-14522 is CWE-119.
You can find more information about CVE-2018-14522 at the following sources: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-14522), [GitHub](https://github.com/aubio/aubio/issues/188), [openSUSE](http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00031.html).